Cannot Use AD Group Push to Manage Groups in the AWS Delegated Groups OU
Last Updated:
Overview
When attempting to configure AD Group Push to manage groups within the AWS Delegated Groups OU on an AD server in AWS, the following error appears:
Unable to update Group Push mapping target App group
{Group Name Here}: Error updating AD groups: Access is Denied. Verify your configuration settings and if necessary delete this push group and reconfigure
Applies To
- AWS Managed AD
- Push Groups
Solution
Due to restrictive permissions on the AWS Delegated Groups Organizational Unit (OU) in Amazon's AWS Managed AD and extraneous operations performed by Okta's AD agent, Admins cannot use Okta's Push Groups feature to control membership of groups that reside in the AWS Delegated Groups OU. If Admins attempt to configure the Push Groups feature on a group that resides in the AWS Delegated Groups OU, it will fail with the following message:
Unable to update Group Push mapping target App group <group name>: Error updating AD Group: Access is denied.
